๐ต๏ธ RESEARCH & DEEP DIVES
- Certighost AD Exploit and Check Point 0-day Actively Exploited
Multiple critical vulnerabilities and active exploits affected enterprise security products and infrastructure this week.- Active Directory Certighost flaw (
CVE-2026-54121) lets low-privilege users impersonate Domain Controllers - Check Point SmartConsole authentication bypass (
CVE-2026-16232) actively exploited for admin access - HTTP/2 DoS bugs (
CVE-2026-44909,CVE-2026-59173,CVE-2026-59762) cause server memory exhaustion - Notepad++ plugin hijacked via phishing, deploying trojan DLLs for persistence and payload delivery
- Palo Alto PAN-OS authentication bypass (
CVE-2026-0257) exploited to deploy ransomware and steal AD data
๐ Coverage: cybersecuritynews.com ยท ๐ Original: cybersecuritynews.com ยท ๐ via Cyber Security News
- Active Directory Certighost flaw (
๐ต๏ธ RESEARCH & DEEP DIVES
- Claude AI Shared Chats Exposed in Google Search Results
Claude AI shared chat links were publicly indexed by Google, exposing sensitive conversations.- Applies to Anthropic Claude AI users sharing conversations via public URLs
- Shared chats included legal advice, engineering work, and personal discussions
- Exposure occurred because shared links lacked noindex tags, allowing Google to index them
- Discovery made via Reddit; hundreds of chats were accessible without direct links
- Google results largely removed after issue surfaced, but saved URLs may still grant access
๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News